CVE-2026-17084

medium

Description

The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Unicode 3.2.0. This behavior would cause mismatches when processing domain names using IDNA 2003 (the "idna" codec) and the in_table_b2() function of the "stringprep" module. This only affects domain names containing characters that were not previously registered or had their Unicode attributes such as case-folding behavior updated since Unicode 3.2.0.

References

https://mail.python.org/archives/list/[email protected]/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/

https://github.com/python/cpython/pull/155293

https://github.com/python/cpython/issues/155292

https://github.com/python/cpython/commit/c42790b34f634051750e5da340d17c7da19e4784

https://github.com/python/cpython/commit/c28b121a4f0b975937c8b5a1b4934bb361d84296

https://github.com/python/cpython/commit/c016c2535b74227fddf2cf7334dbfead6c930214

https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc

https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7

https://github.com/python/cpython/commit/1e54caa096678a38afcabecabb1ff72400dd6bae

http://www.openwall.com/lists/oss-security/2026/08/18/2

Details

Source: Mitre, NVD

Published: 2026-08-18

Updated: 2026-09-10

Risk Information

CVSS v2

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 5.3

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Severity: Medium

CVSS v4

Base Score: 6

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Severity: Medium

EPSS

EPSS: 0.00511